A wallet has drained 3,832 NFTs from hundreds of wallets, raising concerns among NFT holders about a possible security problem. An X user flagged the activity and warned people holding valuab
A wallet has drained 3,832 NFTs from hundreds of wallets, raising concerns among NFT holders about a possible security problem. An X user flagged the activity and warned people holding valuable NFTs to consider revoking wallet permissions as a precaution.
The wallet carrying the NFTs appeared to have been funded by an address linked to 0xQuit, an X user and Yuga Labs Vice President of Blockchain. 0xQuit has previously taken part in similar rescue efforts. In June 2026, he was part of a team that removed 68 NFTs worth about $500,000 from Flooring after an exploit, holding them temporarily before returning them once the project’s developers resolved the issue.
0xQuit later confirmed that the latest move was also a whitehat rescue. He said the NFTs would be returned once they were no longer at risk.
The move has still sparked a debate over whether taking users’ NFTs without permission can be justified, even when the goal is to protect them. One user called the action “gray hat,” arguing that draining the NFTs first could make owners panic because their assets appear to be gone, even if they are later returned.
Another user defended the move, saying leaving the security problem open could have allowed someone else to take the NFTs and keep them permanently. Magic Eden, the marketplace believed to be linked to the security issue, had not publicly commented at the time of writing.
You may also like: California Authorities Crack Down on Crypto Scams
OpenSea has faced similar wallet-draining attacks
Magic Eden isn’t the first big marketplace to have wallets drained through this kind of vulnerability, OpenSea has been through nearly identical episodes more than once. In February 2022, attackers exploited a flaw tied to OpenSea’s older smart contract system, tricking users into signing what looked like a routine listing but actually handed over permission for their NFTs to be transferred out, letting the attacker buy valuable NFTs off victims for a fraction of a cent before flipping them.
Around the same period, OpenSea users who claimed an airdropped NFT found other items in their wallet disappearing shortly after, another case of a signature approval being abused. One victim of a separate 2022 OpenSea exploit lost a Bored Ape worth close to 100 times what the attacker paid for it, and later sued the platform after OpenSea failed to help him recover it or offer compensation, a case his lawyer described at the time as having no real precedent to draw on.
Whatever caused this week’s Magic Eden incident, the underlying weakness, a wallet permission being exploited to move NFTs without the owner’s real consent, is one of the most repeated failure points across NFT marketplaces generally, not a problem unique to any single platform.
NFT drainers are built to steal from many wallets at once
Incidents like this often involve wallet drainers, malicious tools designed to trick people into giving up access to their tokens. In 2024 alone, security researchers at Scam Sniffer tracked $494 million stolen through these attacks from about 332,000 victims, a 67% increase from the previous year.
These drainers are built to target large numbers of wallets rather than just one person at a time. Some are sold as ready-to-use services on Telegram under names such as Inferno, Angel and Pink Drainer. They can include fake airdrop pages, hijacked Discord posts, and cloned websites that look almost identical to legitimate ones.
The attacks usually depend on a single moment of trust. A user may think they are approving a normal transaction, minting an NFT or claiming a reward, while the signature actually gives the attacker permission to move their tokens. That makes the scale of this week’s Magic Eden incident notable. If the 3,832 NFTs were taken through a similar wallet permission problem, the incident shows how one weakness can affect hundreds of wallets at once.
Enjoyed this? BookmarkDeFi Planet, explore related topics, and follow us onTwitter,LinkedIn,Facebook,Instagram,Threads, and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.
The post Magic Eden Suspected of NFT Security Vulnerability as White Hat Moves 3,832 NFTs appeared first on DeFi Planet.